Enum Class IssuanceWarrant.Form

java.lang.Object
java.lang.Enum<IssuanceWarrant.Form>
xyz.tcheeric.cashu.voucher.domain.IssuanceWarrant.Form
All Implemented Interfaces:
Serializable, Comparable<IssuanceWarrant.Form>, Constable
Enclosing class:
IssuanceWarrant

public static enum IssuanceWarrant.Form extends Enum<IssuanceWarrant.Form>
The four shapes a warrant can take.

One field, four forms, so every verifier has one code path and an unknown shape is refused rather than guessed at.

  • Enum Constant Details

    • MERCHANT

      public static final IssuanceWarrant.Form MERCHANT
      The stall itself signed the sale digest. Verifiable offline against issuer.

      This is prevention: a compromised issuing service cannot produce one, because it does not hold the stall's key.

    • PROCESSOR

      public static final IssuanceWarrant.Form PROCESSOR
      A payment processor moved money into the stall's own account.

      A claim, not a proof, at verification time. The issuing service is the thing that reads the processor, so a compromised service can assert a charge that does not exist. What changes is that the assertion is falsifiable by a party outside the trust boundary: the stall, reading its own dashboard, resolves it to "no such charge". The forgery survives the instant and does not survive reconciliation.

      It is also economically self-defeating. Forging a large coupon this way requires routing that much real money into the victim's own account.

    • DELEGATED

      public static final IssuanceWarrant.Form DELEGATED
      A terminal credential the stall issued, and can burn, signed the digest.

      Prevention, and revocable. Verification is two steps: the signature against the credential's lock key, then that the credential was minted by issuer. Doing only the first accepts a credential the attacker minted for themselves.

    • NONE

      public static final IssuanceWarrant.Form NONE
      Nothing outside the issuing service authorised this, and the issuer has SIGNED that.

      Not the same as an absent tag. An absent tag means the voucher predates warrants and the issuer said nothing; NONE is a positive statement. Conflating them lets a compromised service strip a warrant and have it read as legacy.

  • Method Details

    • values

      public static IssuanceWarrant.Form[] values()
      Returns an array containing the constants of this enum class, in the order they are declared.
      Returns:
      an array containing the constants of this enum class, in the order they are declared
    • valueOf

      public static IssuanceWarrant.Form valueOf(String name)
      Returns the enum constant of this class with the specified name. The string must match exactly an identifier used to declare an enum constant in this class. (Extraneous whitespace characters are not permitted.)
      Parameters:
      name - the name of the enum constant to be returned.
      Returns:
      the enum constant with the specified name
      Throws:
      IllegalArgumentException - if this enum class has no constant with the specified name
      NullPointerException - if the argument is null
    • wire

      public String wire()
      The lowercase token that appears on the wire.
    • fromWire

      public static IssuanceWarrant.Form fromWire(String value)
      Parses a wire token, or throws.

      Throws rather than returning null or a default: an unrecognised form is a voucher produced by something this build does not understand, and treating it as NONE would silently downgrade it.